Latest CVE Feed
-
1.9
LOWCVE-2009-1215
Race condition in GNU screen 4.0.3 allows local users to create or overwrite arbitrary files via a symlink attack on the /tmp/screen-exchange temporary file.... Read more
- Published: Apr. 01, 2009
- Modified: Apr. 09, 2025
-
1.9
LOWCVE-2004-2713
Zone Alarm Pro 1.0 through 5.1 gives full access to %windir%\Internet Logs\* to the EVERYONE group, which allows local users to cause a denial of service by modifying the folder contents or permissions. NOTE: this issue has been disputed by the vendor, wh... Read more
Affected Products : zonealarm- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
1.9
LOWCVE-2015-3785
The Telephony component in Apple OS X before 10.11, when the Continuity feature is enabled, allows local users to bypass intended telephone-call restrictions via unspecified vectors.... Read more
- Published: Oct. 09, 2015
- Modified: Apr. 12, 2025
-
1.9
LOWCVE-2006-6698
The GConf daemon (gconfd) in GConf 2.14.0 creates temporary files under directories with names based on the username, even when GCONF_GLOBAL_LOCKS is not set, which allows local users to cause a denial of service by creating the directories ahead of time,... Read more
Affected Products : gconf- Published: Dec. 22, 2006
- Modified: Apr. 09, 2025
-
1.9
LOWCVE-2002-2283
Microsoft Windows XP with Fast User Switching (FUS) enabled does not remove the "show processes from all users" privilege when the user is removed from the administrator group, which allows that user to view processes of other users.... Read more
Affected Products : windows_xp- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
1.9
LOWCVE-2015-1681
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow local users to cause a denial of service via a crafted .msc file, aka "Microsoft Man... Read more
Affected Products : windows_7 windows_8.1 windows_rt_8.1 windows_server_2008 windows_server_2012 windows_vista windows_8 windows_rt- Published: May. 13, 2015
- Modified: Apr. 12, 2025
-
1.9
LOWCVE-2008-3876
Apple iPhone 2.0.2, in some configurations, allows physically proximate attackers to bypass intended access restrictions, and obtain sensitive information or make arbitrary use of the device, via an Emergency Call tap and a Home double-tap, followed by a ... Read more
Affected Products : iphone- Published: Sep. 02, 2008
- Modified: Apr. 09, 2025
-
1.9
LOWCVE-2011-0006
The ima_lsm_rule_init function in security/integrity/ima/ima_policy.c in the Linux kernel before 2.6.37, when the Linux Security Modules (LSM) framework is disabled, allows local users to bypass Integrity Measurement Architecture (IMA) rules in opportunis... Read more
Affected Products : linux_kernel- Published: Jun. 21, 2012
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2010-4079
The ivtvfb_ioctl function in drivers/media/video/ivtv/ivtvfb.c in the Linux kernel before 2.6.36-rc8 does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via... Read more
- Published: Nov. 29, 2010
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2010-3431
The privilege-dropping implementation in the (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) 1.1.2 does not check the return value of the setfsuid system call, which might allow local users to obtain sensitive information by leveraging an unin... Read more
- Published: Jan. 24, 2011
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2010-2803
The drm_ioctl function in drivers/gpu/drm/drm_drv.c in the Direct Rendering Manager (DRM) subsystem in the Linux kernel before 2.6.27.53, 2.6.32.x before 2.6.32.21, 2.6.34.x before 2.6.34.6, and 2.6.35.x before 2.6.35.4 allows local users to obtain potent... Read more
- Published: Sep. 08, 2010
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2010-2192
The make_lockdir_name function in policy.c in pmount 0.9.18 allow local users to overwrite arbitrary files via a symlink attack on a file in /var/lock/.... Read more
Affected Products : pmount- Published: Jun. 18, 2010
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2005-2186
Multiple cross-site scripting (XSS) vulnerabilities in McAfee IntruShield Security Management System allow remote authenticated users to inject arbitrary web script or HTML via the (1) thirdMenuName or (2) resourceName parameter to SystemEvent.jsp.... Read more
Affected Products : intrushield_security_management_system- Published: Jul. 11, 2005
- Modified: Apr. 03, 2025
-
1.9
LOWCVE-2024-53855
Centurion ERP (Enterprise Rescource Planning) is a simple application developed to provide open source IT management with a large emphasis on the IT Service Management (ITSM) modules. A user who is authenticated and has view permissions for a ticket, can ... Read more
Affected Products : centurion_erp- Published: Nov. 27, 2024
- Modified: Nov. 27, 2024
-
1.9
LOWCVE-2010-2470
Install/Filesystem.pm in Bugzilla 3.5.1 through 3.6.1 and 3.7 through 3.7.1, when use_suexec is enabled, uses world-readable permissions within (1) .bzr/ and (2) data/webdot/, which allows local users to obtain potentially sensitive data by reading files ... Read more
Affected Products : bugzilla- Published: Jun. 28, 2010
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2009-2490
Unspecified vulnerability in the utaudiod daemon in Sun Ray Server Software (SRSS) 4.0, when Solaris Trusted Extensions is enabled, allows local users to cause a denial of service (audio outage) or possibly gain privileges via unknown vectors related to "... Read more
Affected Products : ray_server_software- Published: Jul. 16, 2009
- Modified: Apr. 09, 2025
-
1.9
LOWCVE-2009-1296
The eCryptfs support utilities (ecryptfs-utils) 73-0ubuntu6.1 on Ubuntu 9.04 stores the mount passphrase in installation logs, which might allow local users to obtain access to the filesystem by reading the log files from disk. NOTE: the log files are on... Read more
- Published: Jun. 09, 2009
- Modified: Apr. 09, 2025
-
1.9
LOWCVE-2012-0098
Unspecified vulnerability in Oracle Solaris 8, 9, 10, and 11 Express allows local users to affect availability via unknown vectors related to Kernel, a different vulnerability than CVE-2011-0813.... Read more
- Published: Jan. 18, 2012
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2010-1650
IBM WebSphere Application Server (WAS) 6.0.x before 6.0.2.41, 6.1.x before 6.1.0.31, and 7.0.x before 7.0.0.11, when the -trace option (aka debugging mode) is enabled, executes debugging statements that print string representations of unspecified objects,... Read more
Affected Products : websphere_application_server- Published: May. 03, 2010
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2013-4481
Race condition in Luci 0.26.0 creates /var/lib/luci/etc/luci.ini with world-readable permissions before restricting the permissions, which allows local users to read the file and obtain sensitive information such as "authentication secrets."... Read more
- Published: Nov. 23, 2013
- Modified: Apr. 11, 2025